DNS_PROBE_FINISHED_NXDOMAIN — Domain Doesn't Resolve

NXDOMAIN means the resolver asked an authoritative server and the name simply doesn't exist — for your resolver's view. Most cases are stale local cache, wrong record, or propagation lag.

What you'll see

Root causes

Stale negative cache

Resolvers cache 'does not exist' answers. If you just created the record, your resolver may still be serving the cached miss. dig @1.1.1.1 <host> +short tests a different resolver's view.

Record created at the wrong level or wrong zone

An A record for app.example.com must live in the example.com zone. A typo in the zone file (missing trailing dot: 'app.example.com example.com.') silently creates a name like app.example.com.example.com.

Nameservers not delegated or registrar glue missing

dig NS example.com +short shows which nameservers the world is told to ask. If they don't match where you created the record, delegation is the problem.

Fix it

  1. Compare resolvers and read the authority section
    dig example.com +nostats +authority   # SOA in authority = record genuinely absent upstream
  2. Verify the record exists at its authoritative source
    dig @<your-nameserver-ip> app.example.com +short   # bypass caches entirely
  3. Flush local caches (client and OS)
    # Chrome: chrome://net-internals/#dns  |  systemd: sudo resolvectl flush-caches  |  macOS: sudo dscacheutil -flushcache
  4. Check delegation from the parent zone
    dig NS example.com +short && dig example.com SOA +short

Field note

Negative caching honors the SOA minimum TTL — a fresh record can be 'invisible' for up to that long on some resolvers. dig +trace shows the full delegation chain from the root — the definitive propagation test.

Common questions

My domain works for me but not for others — why?

Their resolver cached the NXDOMAIN answer before you created the record. It will expire on its own; you can verify correctness against the authoritative server with dig @<ns-ip> in the meantime.

How long until a new DNS record is visible everywhere?

There's no global answer: each resolver caches independently. Global propagation typically completes within hours because negative-cache TTLs for NXDOMAIN are short, but plan for up to a day.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.